KYB, AML, and OFAC: The Compliance Behind Dental Crypto Payments, Demystified

By DDSCrypto Editorial Team

Published July 19, 2026

TL;DR

KYB, AML, and OFAC are compliance checks that a regulated crypto payment processor runs — verifying the dental practice at onboarding, monitoring transactions for suspicious patterns, and screening counterparties against US sanctions lists. The dental practice doesn't perform any of this work itself; it simply gets verified once and then receives locked-rate, same-day USD payments. Understanding the acronyms turns them from scary jargon into a reason patients and partners can trust the payment rail.

KYB (Know Your Business), AML (Anti-Money Laundering), and OFAC (Office of Foreign Assets Control) screening are compliance checks a regulated crypto payment processor runs — not something a dental practice has to build, staff, or maintain itself†. The practice completes a one-time verification at signup, and after that, every payment is automatically screened in the background while the practice simply receives locked-rate, same-day USD settlement. Far from a red flag, these acronyms are the reason a crypto payment rail can be trusted with a patient's money in the first place.

If the first time someone mentioned "KYB, AML, and OFAC" to you was in a sales call about accepting crypto payments, the natural reaction is suspicion — that's a lot of alphabet soup for what sounds like it should be as simple as swiping a card. This article exists to take the mystery out of those three acronyms, explain who is actually doing the work behind them, and show why a practice that understands this compliance layer ends up more confident in the rail, not less.

What do KYB, AML, and OFAC actually stand for?

Three different things, each covering a different moment in the payment lifecycle:

  • KYB — Know Your Business. A one-time verification, done when a merchant (like a dental practice) signs up with a payment processor, confirming who the business is, who owns it, and that it's a legitimate operating entity†.
  • AML — Anti-Money Laundering. An ongoing program — not a single check — where a processor monitors transaction patterns for signs consistent with money laundering or structuring, and maintains the internal controls regulators require of it†.
  • OFAC — Office of Foreign Assets Control. A US Treasury office that maintains sanctions lists of individuals, entities, and jurisdictions Americans are barred from transacting with; "OFAC screening" means checking a payment's counterparties against those lists†.

None of these are unique to crypto. Every bank, card network, and payment processor in the country runs some version of all three today†. The reason they get named explicitly in the crypto context is that crypto payment processors are newer and less familiar, so they tend to describe their compliance stack out loud — where a legacy card processor's version of the same work is buried inside decades-old, invisible infrastructure.

Why does a dental practice need to care about acronyms meant for banks?

Short answer: mostly, it doesn't need to do anything with them — but it's worth understanding what they mean, because they answer the question every skeptical patient or partner eventually asks: "Is this actually safe, or did you just start accepting some sketchy internet money?"

A practice that can say, in plain language, "our payment processor verifies every merchant, monitors transactions for fraud, and screens against government sanctions lists" is describing a compliance posture that's arguably more rigorous — or at least more explicitly documented — than what most patients assume happens when they tap a debit card. The acronyms sound scary because they're unfamiliar, not because they represent something risky.

What does KYB verification actually involve when a practice signs up?

For the dental practice, KYB is a front-loaded, one-time step — not a recurring burden. It typically covers:

  • Legal business name, entity type, and ownership structure†
  • NPI number or state dental license information, confirming the practice is a real, operating healthcare business†
  • Estimated monthly payment volume, to size the account appropriately
  • Basic identity verification of the practice's authorized signer(s)†

This is the same category of information a bank or a card-processing application already collected when the practice opened its merchant account or business checking account — nothing crypto-specific about the type of information being verified, just a new party doing the verifying. Most practices complete this step in a matter of minutes as part of the broader onboarding process, which typically wraps in about a week from application to first live payment.

What is AML, and how does "monitoring" actually work on a patient's crypto payment?

AML is where the "ongoing" part of compliance lives. Rather than a single check at signup, it's a continuous program the processor runs across every transaction that flows through it, looking for patterns — not individual payments — that resemble money laundering or structuring†. In practice, that means things like:

  • Watching for unusual volume spikes or patterns inconsistent with a dental practice's normal business
  • Flagging transactions that don't match the expected size or frequency for the merchant type
  • Maintaining the internal controls, a compliance officer, and independent testing that regulators expect of a money services business†

For a dental office running normal patient transactions — a $200 cleaning, a $6,400 implant case, a $12,000 full-arch case — this program runs invisibly. It exists to catch the rare bad actor trying to abuse a payment rail, not to interrogate a patient paying for a crown. The practice never has to build, staff, or file anything related to this program itself; it's entirely the processor's regulatory obligation†.

What is OFAC screening, and could it ever block a patient's payment?

OFAC screening is the practice of checking the parties in a transaction against the US Treasury's sanctioned-persons and sanctioned-entities lists†. It's automated, it runs on essentially every payment across the regulated financial system — cards, wires, ACH, and crypto alike — and for the overwhelming majority of transactions, it's invisible because there's nothing on the list to match.

In the ordinary course of a dental practice's patient payments, OFAC screening isn't something staff will ever see or think about — it runs in the background of the same locked-rate-to-same-day-settlement flow described in the pillar guide to accepting cryptocurrency at a dental practice. It exists as a safeguard, not a speed bump, for the vast majority of routine patient care payments†.

Who's actually doing this work — the practice, or the processor?

The processor. This is the single most important thing to understand about the whole compliance stack, and it's worth restating plainly:

Compliance layerWhat it checksWho performs itWhen it happens
KYBBusiness identity, ownership, licensurePayment processorOnce, at merchant onboarding
AMLTransaction patterns across the merchant's accountPayment processorContinuously, in the background
OFACSanctioned-persons/entities listsPayment processorAutomatically, per transaction
Recordkeeping / reportingBSA-style records, suspicious activity reportsPayment processorOngoing, as required by regulators†
Practice's roleConfirms its own business details onceDental practiceOne-time, at signup

A properly built crypto payment processor is expected to register with FinCEN as a money services business, hold (or be exempt from) state money transmitter licensing, and maintain the AML program and OFAC screening capability described above†. None of that licensing burden or ongoing compliance obligation passes through to the dental practice, provided the practice's role stays limited to being a merchant that gets paid — never converting or moving crypto on behalf of others†.

How is this different from what a card processor already does?

It isn't, fundamentally — it's the same category of work, just less visible because it's decades older and buried inside card-network infrastructure most people never think about†. Every time a practice's existing card processor approves a Visa or Mastercard transaction, similar merchant-vetting, fraud-monitoring, and sanctions-screening machinery is running behind the scenes at the acquiring bank and card network level†.

The difference isn't the type of compliance — it's that crypto processors, being newer, tend to describe their compliance program out loud, using acronyms that sound novel simply because they're unfamiliar in a dental-office context. A practice that already trusts its card processor to handle merchant compliance invisibly is, functionally, being asked to extend the same trust to a crypto processor that's just more explicit about naming the work.

Does any of this slow down settlement?

No, in the ordinary case†. KYB happens once, up front, not on every transaction — so it has zero bearing on how fast an individual patient payment settles. AML monitoring and OFAC screening run automatically and near-instantaneously as part of the payment confirmation, the same way a card network's fraud model runs in the milliseconds before a swipe is approved. None of it interferes with the mechanics that make a crypto payment rail attractive in the first place: the rate locks at checkout, the payment converts on confirmation, and USD settles to the practice's bank account the same day — a meaningfully faster settlement window than, for comparison, BitPay's next-business-day model.

Can this compliance work actually become a trust signal for the practice?

Yes — and this is the reframe worth internalizing. Most patients and referral partners who hear "crypto payments" default to skepticism, picturing something unregulated or fringe. A practice that can explain, in plain terms, that its processor verifies every merchant, monitors every transaction pattern, and screens against federal sanctions lists is describing infrastructure that sounds — and is — more actively monitored than the mental model most people have of "just tapping a card."

That's a genuinely useful thing to be able to say to a patient who asks "is this safe?" or to a partner dentist evaluating whether to add the rail: the acronyms that sound intimidating on first read are, on inspection, exactly the reason the rail can be trusted with real money moving through it. Turning KYB/AML/OFAC into a talking point rather than a disclaimer is a small but real differentiator for a practice that wants to look forward-thinking without looking reckless.

What should a practice confirm before trusting a processor's compliance claims?

A short, practical list, worth working through with whichever processor a practice is evaluating:

  1. Is the processor registered with FinCEN as a money services business, and licensed (or properly exempt) in relevant states†?
  2. Does the practice ever touch or hold crypto directly, or is settlement 100% in USD?
  3. Is KYB a one-time onboarding step, or does it recur in a way that creates ongoing friction?
  4. Does the processor maintain a documented AML program and OFAC screening capability, and can it describe that program in plain terms†?
  5. How fast is settlement — same-day, or slower?
  6. Does the merchant agreement clearly state that the processor, not the practice, carries the money-transmission and compliance obligations?

These are largely the same questions worth asking any payment partner, card or crypto — the answers just happen to be less commonly volunteered by legacy processors, since the underlying compliance work has been standardized and invisible in card networks for decades.

Bottom line

KYB, AML, and OFAC sound like regulatory jargon because they are — but they describe compliance work a licensed payment processor performs, not a burden a dental practice takes on. The practice's part is a one-time verification at signup; everything after that — pattern monitoring, sanctions screening, recordkeeping — runs in the background of a payment flow that still locks the rate at checkout and settles same-day USD to the practice's existing bank account†. Understood correctly, these acronyms aren't a reason to hesitate on a crypto payment rail — they're the reason it's safe to trust one.

For the fuller mechanics of how a compliant, USD-settlement crypto rail works end to end, see the pillar guide to accepting cryptocurrency at a dental practice, check current rates on the pricing page, or browse more compliance and cost breakdowns on the DDSCrypto blog.

DDSCrypto is a payment processor for dental practices — not a cryptocurrency, and unrelated to Dentacoin (DCN), a separate 2017 token.

† Pending counsel review; not legal or tax advice.

Frequently asked questions

What do KYB, AML, and OFAC actually stand for?
KYB is Know Your Business (verifying a merchant's identity and ownership at onboarding), AML is Anti-Money Laundering (ongoing monitoring for suspicious transaction patterns), and OFAC is the US Treasury's Office of Foreign Assets Control, which maintains sanctions lists that counterparties get screened against†.
Does a dental practice have to run its own KYB, AML, or OFAC program?
No† — a licensed, regulated payment processor is the one that registers, builds compliance programs, and executes these checks. The dental practice completes a one-time KYB verification at signup and then simply gets paid; it doesn't maintain an AML program or run sanctions screening itself.
What does KYB verification actually involve for a dental practice signing up?
Typically basic business details — legal entity name, ownership, NPI or license information, and estimated payment volume† — similar to what a bank or card processor already collected when the practice opened its merchant account.
Could a patient's crypto payment ever get blocked or delayed by OFAC screening?
In the ordinary course, no — OFAC screening runs automatically in the background against sanctioned-persons and sanctioned-entity lists, and it's built to catch the rare bad actor, not to slow down a routine patient paying for a cleaning or a crown†.
How is this different from what a credit card processor already does?
It isn't fundamentally different† — card networks, acquiring banks, and card processors already run KYB-style merchant vetting and AML/sanctions screening behind the scenes. Crypto processors are doing the same category of work; it's simply newer infrastructure and less familiar by name.
Does this compliance work slow down same-day settlement?
No — KYB happens once, at onboarding, not on every transaction, and AML/OFAC screening on individual payments runs automatically in the background without adding meaningful delay to the locked-rate-to-same-day-settlement flow†.
Can a dental practice tell patients its payment processor is KYB/AML/OFAC compliant?
Yes, generally, in plain language† — describing a processor as "a regulated, compliance-checked payment provider" is a fair, verifiable statement to make to patients, though any specific licensing claims should be confirmed against the processor's actual registrations first.
Who is legally responsible if a compliance issue arises with a crypto payment?
The regulated payment processor carries the money-services-business and compliance obligations, not the dental practice, as long as the practice's role stays limited to being a merchant that gets paid rather than one that moves or converts crypto for others†.
DDSCrypto is a payment processor for dental practices — not a cryptocurrency, and unrelated to Dentacoin (DCN), a separate 2017 oral-health token.